{
  "day": "2026-05-20",
  "boundary": "UTC calendar day",
  "published_count": 207,
  "by_severity": {
    "CRITICAL": 29,
    "HIGH": 72,
    "MEDIUM": 98,
    "LOW": 3
  },
  "kev_count": 7,
  "exploit_reference_count": 1,
  "awaiting_enrichment_count": 5,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2008-4250",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.98751,
      "epss_percentile": 0.99923,
      "kev": true,
      "kev_due_at": "2026-06-03",
      "vendor": "Microsoft",
      "product": "Windows",
      "cwe": null,
      "title": "Microsoft Windows",
      "url": "https://www.cve.org/CVERecord?id=CVE-2008-4250"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2010-0249",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.91885,
      "epss_percentile": 0.9981,
      "kev": true,
      "kev_due_at": "2026-06-03",
      "vendor": "Microsoft",
      "product": "Internet Explorer",
      "cwe": null,
      "title": "Microsoft Internet Explorer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2010-0249"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2009-3459",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.86583,
      "epss_percentile": 0.99723,
      "kev": true,
      "kev_due_at": "2026-06-03",
      "vendor": "Adobe",
      "product": "Acrobat and Reader",
      "cwe": null,
      "title": "Adobe Acrobat and Reader",
      "url": "https://www.cve.org/CVERecord?id=CVE-2009-3459"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2010-0806",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.82172,
      "epss_percentile": 0.99628,
      "kev": true,
      "kev_due_at": "2026-06-03",
      "vendor": "Microsoft",
      "product": "Internet Explorer",
      "cwe": null,
      "title": "Microsoft Internet Explorer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2010-0806"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-45498",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.63076,
      "epss_percentile": 0.99135,
      "kev": true,
      "kev_due_at": "2026-06-03",
      "vendor": "Microsoft",
      "product": "Microsoft Defender Antimalware Platform",
      "cwe": "CWE-400",
      "title": "Microsoft Defender Denial of Service Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45498"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2009-1537",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.51207,
      "epss_percentile": 0.98844,
      "kev": true,
      "kev_due_at": "2026-06-03",
      "vendor": "Microsoft",
      "product": "DirectX",
      "cwe": null,
      "title": "Microsoft DirectX",
      "url": "https://www.cve.org/CVERecord?id=CVE-2009-1537"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-41091",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.09641,
      "epss_percentile": 0.95091,
      "kev": true,
      "kev_due_at": "2026-06-03",
      "vendor": "Microsoft",
      "product": "Microsoft Malware Protection Engine",
      "cwe": "CWE-59",
      "title": "Microsoft Defender Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41091"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-23734",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.19559,
      "epss_percentile": 0.97163,
      "kev": false,
      "kev_due_at": null,
      "vendor": "xwiki",
      "product": "xwiki-commons",
      "cwe": "CWE-23",
      "title": "XWiki Platform: Path traversal via resources parameter in ssx and jsx endpoints when using leading slash",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-23734"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-8632",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0411,
      "epss_percentile": 0.89949,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HP Inc",
      "product": "HP Linux Imaging and Printing Software",
      "cwe": "CWE-77",
      "title": "HP Linux Imaging and Printing Software – Potential Escalation of Privilege and Arbitrary Code Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8632"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-24207",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.02552,
      "epss_percentile": 0.83778,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "Triton Inference Server",
      "cwe": "CWE-288",
      "title": "NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an authentication bypass. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, or information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24207"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-5946",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.01874,
      "epss_percentile": 0.77699,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ISC",
      "product": "BIND 9",
      "cwe": "CWE-20",
      "title": "Invalid handling of CLASS != IN",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5946"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-8631",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01814,
      "epss_percentile": 0.76925,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HP Inc",
      "product": "HP Linux Imaging and Printing Software",
      "cwe": "CWE-190",
      "title": "HP Linux Imaging and Printing Software – Potential Escalation of Privilege and Arbitrary Code Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8631"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-3593",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01538,
      "epss_percentile": 0.72867,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ISC",
      "product": "BIND 9",
      "cwe": "CWE-416",
      "title": "Heap use-after-free vulnerability in BIND 9 DNS-over-HTTPS implementation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3593"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-5947",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.01387,
      "epss_percentile": 0.7005,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ISC",
      "product": "BIND 9",
      "cwe": "CWE-362",
      "title": "SIG(0) validation during query flood may lead to undefined behavior",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5947"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-39352",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.01279,
      "epss_percentile": 0.67689,
      "kev": false,
      "kev_due_at": null,
      "vendor": "frappe",
      "product": "frappe",
      "cwe": "CWE-22",
      "title": "Frappe has an Arbitrary File Read via Path Traversal in render_include",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39352"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-33278",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01272,
      "epss_percentile": 0.67556,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NLnet Labs",
      "product": "Unbound",
      "cwe": "CWE-416",
      "title": "Possible arbitrary code execution during DNSSEC validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33278"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-47783",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.01264,
      "epss_percentile": 0.6734,
      "kev": false,
      "kev_due_at": null,
      "vendor": "memcached",
      "product": "memcached",
      "cwe": "CWE-208",
      "title": "In memcached before 1.6.42, username data for SASL password database authentication has a timing side channel because a loop exits as soon as a valid username is found by sasl_server_userdb_checkpass.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47783"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-3039",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.01047,
      "epss_percentile": 0.61522,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ISC",
      "product": "BIND 9",
      "cwe": "CWE-771",
      "title": "BIND 9 server memory exhaustion during GSS-API TKEY negotiation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3039"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-6555",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00978,
      "epss_percentile": 0.59399,
      "kev": false,
      "kev_due_at": null,
      "vendor": "prosolution",
      "product": "ProSolution WP Client",
      "cwe": "CWE-434",
      "title": "ProSolution WP Client <= 2.0.0 - Unauthenticated Arbitrary File Upload via 'files'",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6555"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-8467",
      "cvss_base": 9.5,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00907,
      "epss_percentile": 0.57128,
      "kev": false,
      "kev_due_at": null,
      "vendor": "phenixdigital",
      "product": "phoenix_storybook",
      "cwe": "CWE-94",
      "title": "Unauthenticated remote code execution via HEEx template injection in phoenix_storybook playground",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8467"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-45584",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00852,
      "epss_percentile": 0.55393,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Malware Protection Engine",
      "cwe": "CWE-122",
      "title": "Microsoft Defender Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45584"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-42944",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00842,
      "epss_percentile": 0.55069,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NLnet Labs",
      "product": "Unbound",
      "cwe": "CWE-197",
      "title": "Heap overflow with multiple NSID, COOKIE, PADDING EDNS options",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42944"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-20223",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00835,
      "epss_percentile": 0.5489,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Secure Workload",
      "cwe": "CWE-306",
      "title": "Cisco Secure Workload Unauthorized API Access Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20223"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-9064",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00815,
      "epss_percentile": 0.54252,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Directory Server 11.5 E4S for RHEL 8",
      "cwe": "CWE-770",
      "title": "389-ds-base: 389-ds-base: unbounded ldap controls count in get_ldapmessage_controls_ext() causes cpu and heap amplification (remote dos)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9064"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-9111",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00796,
      "epss_percentile": 0.5361,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in WebRTC in Google Chrome on Linux prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9111"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-43618",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0078,
      "epss_percentile": 0.53109,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RsyncProject",
      "product": "rsync",
      "cwe": "CWE-125",
      "title": "Rsync < 3.4.3 Integer Overflow Information Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43618"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-42959",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00779,
      "epss_percentile": 0.53058,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NLnet Labs",
      "product": "Unbound",
      "cwe": "CWE-824",
      "title": "Crash during DNSSEC validation of malicious content",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42959"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-24217",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00764,
      "epss_percentile": 0.52599,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "BioNeMo Framework",
      "cwe": "CWE-29",
      "title": "NVIDIA BioNeMo Core for Linux contains a vulnerability where a user could cause a path traversal by loading a malicious file. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, and data tampering.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24217"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-24425",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00758,
      "epss_percentile": 0.52376,
      "kev": false,
      "kev_due_at": null,
      "vendor": "twigphp",
      "product": "Twig",
      "cwe": "CWE-693",
      "title": "Twig 2.16.x & 3.9.0-3.25.x Sandbox Bypass via SourcePolicyInterface",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24425"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-7522",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00755,
      "epss_percentile": 0.52268,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SigmaPlugin",
      "product": "Advanced Database Cleaner – Premium",
      "cwe": "CWE-98",
      "title": "Advanced Database Cleaner – Premium <= 4.1.0 - Authenticated (Subscriber+) Local File Inclusion via 'template'",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7522"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-24214",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00719,
      "epss_percentile": 0.51033,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "Triton Inference Server",
      "cwe": "CWE-190",
      "title": "NVIDIA Triton Inference Server contains a vulnerability in the DALI backend where an attacker could cause an integer overflow. A successful exploit of this vulnerability might lead to code execution, data tampering, or denial of service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24214"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-24213",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00716,
      "epss_percentile": 0.50941,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "Triton Inference Server",
      "cwe": "CWE-125",
      "title": "NVIDIA Triton Inference Server contains a vulnerability in the DALI backend where an attacker could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, or information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24213"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-5950",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0066,
      "epss_percentile": 0.48806,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ISC",
      "product": "BIND 9",
      "cwe": "CWE-606",
      "title": "Unbounded resend loop in BIND 9 resolver",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5950"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-24208",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0065,
      "epss_percentile": 0.48385,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "Triton Inference Server",
      "cwe": "CWE-22",
      "title": "NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause a path traversal issue. A successful exploit of this vulnerability might lead to denial of service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24208"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2026-24209",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0065,
      "epss_percentile": 0.48385,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "Triton Inference Server",
      "cwe": "CWE-22",
      "title": "NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause a path traversal issue. A successful exploit of this vulnerability might lead to denial of service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24209"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-39047",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00648,
      "epss_percentile": 0.483,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-121",
      "title": "Buffer Overflow vulnerability in EPSON L14150 FL27PB allows a remote attacker to execute arbitrary code via the RAW Printing Service (JetDirect) on TCP port 9100",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39047"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-40092",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00626,
      "epss_percentile": 0.47315,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nimiq",
      "product": "core-rs-albatross",
      "cwe": "CWE-252",
      "title": "nimiq-keys: Unchecked Ed25519 signature length in TaggedPublicKey::verify causes remote node panic via DHT",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40092"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-44390",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00625,
      "epss_percentile": 0.47294,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NLnet Labs",
      "product": "Unbound",
      "cwe": "CWE-407",
      "title": "Unbounded name compression in certain cases causes degradation of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44390"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-41292",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00625,
      "epss_percentile": 0.47295,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NLnet Labs",
      "product": "Unbound",
      "cwe": "CWE-407",
      "title": "Long list of incoming EDNS options degrades performance",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41292"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2026-24210",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00602,
      "epss_percentile": 0.46195,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "Triton Inference Server",
      "cwe": "CWE-190",
      "title": "NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an integer overflow. A successful exploit of this vulnerability might lead to denial of service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24210"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2026-24163",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00594,
      "epss_percentile": 0.45785,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "TensorRT-LLM",
      "cwe": "CWE-502",
      "title": "NVIDIA TRT-LLM for any platform contains a vulnerability in RPC testing, where an attacker could cause an unsafe deserialization. A successful exploit of this vulnerability might lead to code execution, denial of service, data tampering, and information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24163"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-33137",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00594,
      "epss_percentile": 0.45811,
      "kev": false,
      "kev_due_at": null,
      "vendor": "xwiki",
      "product": "xwiki-platform",
      "cwe": "CWE-862",
      "title": "XWiki Platform has an Unauthenticated XAR Import via REST /wikis/{wikiName}",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33137"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-24218",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00586,
      "epss_percentile": 0.45429,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "DGX Spark",
      "cwe": "CWE-321",
      "title": "NVIDIA DGX OS contains a vulnerability in the factory provisioning process, where the cloning of a base image causes identical SSH host keys to be deployed across multiple systems. The sharing of cryptographic identifiers across all similarly provisioned systems enables host impersonation or attacker-in-the-middle attacks. A successful exploit of this vulnerability might lead to code execution, data tampering, escalation of privileges, information disclosure, and denial of service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24218"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2026-42534",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00583,
      "epss_percentile": 0.45308,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NLnet Labs",
      "product": "Unbound",
      "cwe": "CWE-440",
      "title": "Jostle logic bypass degrades resolution performance",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42534"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-7637",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00573,
      "epss_percentile": 0.44809,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PixelYourSite",
      "product": "Boost",
      "cwe": "CWE-502",
      "title": "Boost <= 2.0.3 - Unauthenticated PHP Object Injection via STYXKEY-BOOST_USER_LOCATION Cookie",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7637"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2025-33255",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00566,
      "epss_percentile": 0.44472,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "TensorRT-LLM",
      "cwe": "CWE-502",
      "title": "NVIDIA TRT-LLM for any platform contains a vulnerability in MPI server, where an attacker could cause an unsafe deserialization. A successful exploit of this vulnerability might lead to code execution, denial of service, data tampering, and information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-33255"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2026-9102",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00563,
      "epss_percentile": 0.44352,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Altium",
      "product": "Altium Enterprise Server",
      "cwe": "CWE-22",
      "title": "Path Traversal in Altium Enterprise Server ComparisonService Allows Arbitrary File Write",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9102"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2026-47784",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0055,
      "epss_percentile": 0.43622,
      "kev": false,
      "kev_due_at": null,
      "vendor": "memcached",
      "product": "memcached",
      "cwe": "CWE-208",
      "title": "In memcached before 1.6.42, password data for SASL password database authentication has a timing side channel because memcmp is used by sasl_server_userdb_checkpass.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47784"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-24206",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00549,
      "epss_percentile": 0.43585,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "Triton Inference Server",
      "cwe": "CWE-288",
      "title": "NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an authentication bypass. A successful exploit of this vulnerability might lead to escalation of privileges, denial of service, or information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24206"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2026-9003",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00539,
      "epss_percentile": 0.43089,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TONNET",
      "product": "TPR7308",
      "cwe": "CWE-89",
      "title": "TONNET｜E-LAN Hybrid Recording System - SQL Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9003"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2026-9119",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00538,
      "epss_percentile": 0.43004,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-122",
      "title": "Heap buffer overflow in WebRTC in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9119"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2026-8469",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00537,
      "epss_percentile": 0.42956,
      "kev": false,
      "kev_due_at": null,
      "vendor": "phenixdigital",
      "product": "phoenix_storybook",
      "cwe": "CWE-770",
      "title": "Unauthenticated denial-of-service via BEAM atom table exhaustion in phoenix_storybook",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8469"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2026-8598",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00507,
      "epss_percentile": 0.41182,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ZKTeco",
      "product": "SSC335-GC2063-Face-0b77 Solution Camera",
      "cwe": "CWE-288",
      "title": "Unauthenticated Export Service in ZKTeco CCTV Cameras",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8598"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2026-40165",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00502,
      "epss_percentile": 0.40866,
      "kev": false,
      "kev_due_at": null,
      "vendor": "goauthentik",
      "product": "authentik",
      "cwe": "CWE-91",
      "title": "authentik: SAML NameID XML Comment Injection Enables Authentication Bypass via Identifier Truncation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40165"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2026-9120",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00501,
      "epss_percentile": 0.40809,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in WebRTC in Google Chrome prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9120"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2026-7284",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00494,
      "epss_percentile": 0.40386,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themewant",
      "product": "Easy Elements for Elementor – Addons & Website Templates",
      "cwe": "CWE-269",
      "title": "Easy Elements for Elementor <= 1.4.4 - Unauthenticated Privilege Escalation via easyel_handle_register",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7284"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2026-20239",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00485,
      "epss_percentile": 0.39826,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk Enterprise",
      "cwe": "CWE-532",
      "title": "Sensitive Information Disclosure through Log Files in Splunk Enterprise",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20239"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2026-9141",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00481,
      "epss_percentile": 0.39634,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Taiko Network Communications Pte Ltd.",
      "product": "AG1000-01A SMS Alert Gateway",
      "cwe": "CWE-306",
      "title": "Taiko AG1000-01A Rev 7.3/8 Authentication Bypass via Web Interface",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9141"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2026-6072",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00475,
      "epss_percentile": 0.39214,
      "kev": false,
      "kev_due_at": null,
      "vendor": "oliverpos",
      "product": "Oliver POS – A WooCommerce Point of Sale (POS)",
      "cwe": "CWE-639",
      "title": "Oliver POS <= 2.4.2.6 - Unauthenticated Authorization Bypass Through User-Controlled Key to 'OliverAuth' Header",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6072"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2026-24160",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00468,
      "epss_percentile": 0.38731,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "TensorRT-LLM",
      "cwe": "CWE-690",
      "title": "NVIDIA TRT-LLM for any platform contains a vulnerability where an attacker could cause an unchecked return value to a null pointer dereference. A successful exploit of this vulnerability might lead to denial of service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24160"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2026-20171",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00467,
      "epss_percentile": 0.38667,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco NX-OS Software",
      "cwe": "CWE-670",
      "title": "Cisco Nexus 3000 and 9000 Series Border Gateway Protocol Denial of Service Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20171"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2026-39850",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00455,
      "epss_percentile": 0.37919,
      "kev": false,
      "kev_due_at": null,
      "vendor": "yiisoft",
      "product": "yii2",
      "cwe": "CWE-20",
      "title": "Yii 2: Local file inclusion via view parameter name collision",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39850"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2026-9139",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00454,
      "epss_percentile": 0.37808,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Taiko Network Communications Pte Ltd.",
      "product": "AG1000-01A SMS Alert Gateway",
      "cwe": "CWE-798",
      "title": "Taiko AG1000-01A Rev 7.3/8 Hard-coded Credentials via login.zhtml",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9139"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2026-35070",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00451,
      "epss_percentile": 0.37666,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "SmartFabric Storage Software",
      "cwe": "CWE-77",
      "title": "Dell SmartFabric Storage Software, versions prior to 1.4.5, contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Filesystem access for attacker.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35070"
    },
    {
      "rank": 65,
      "cve_id": "CVE-2026-47068",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00449,
      "epss_percentile": 0.375,
      "kev": false,
      "kev_due_at": null,
      "vendor": "phenixdigital",
      "product": "phoenix_storybook",
      "cwe": "CWE-639",
      "title": "Cross-session PubSub topic injection via URL parameter in phoenix_storybook",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47068"
    },
    {
      "rank": 66,
      "cve_id": "CVE-2026-7472",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00448,
      "epss_percentile": 0.37418,
      "kev": false,
      "kev_due_at": null,
      "vendor": "edmonparker",
      "product": "Read More & Accordion",
      "cwe": "CWE-89",
      "title": "Read More & Accordion <= 3.5.7 - Authenticated (Administrator+) SQL Injection via 'orderby' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7472"
    },
    {
      "rank": 67,
      "cve_id": "CVE-2026-9144",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00441,
      "epss_percentile": 0.36892,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Taiko Network Communications Pte Ltd.",
      "product": "AG1000-01A SMS Alert Gateway",
      "cwe": "CWE-79",
      "title": "Taiko AG1000-01A Rev 7.3/8 Stored XSS via Web Configuration Interface",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9144"
    },
    {
      "rank": 68,
      "cve_id": "CVE-2026-20199",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00438,
      "epss_percentile": 0.36649,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco ThousandEyes Enterprise Agent",
      "cwe": "CWE-74",
      "title": "A vulnerability in the SSL certificate handling of Cisco ThousandEyes Virtual Appliance could allow an authenticated, remote attacker to execute commands on the underlying operating system as the root user. This vulnerability is due to insufficient validation of user-supplied input. An authenticated attacker could exploit this vulnerability by uploading a crafted certificate to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system. To exploit this vulnerability, the attacker must have valid administrative credentials.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20199"
    },
    {
      "rank": 69,
      "cve_id": "CVE-2026-43620",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00428,
      "epss_percentile": 0.3585,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RsyncProject",
      "product": "rsync",
      "cwe": "CWE-125",
      "title": "Rsync < 3.4.3 Out-of-Bounds Array Read via recv_files()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43620"
    },
    {
      "rank": 70,
      "cve_id": "CVE-2026-20206",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00416,
      "epss_percentile": 0.34862,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco ThousandEyes Enterprise Agent",
      "cwe": "CWE-78",
      "title": "Cisco ThousandEyes BrowserBot Command Injection Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20206"
    },
    {
      "rank": 71,
      "cve_id": "CVE-2026-24215",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00411,
      "epss_percentile": 0.34419,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "Triton Inference Server",
      "cwe": "CWE-400",
      "title": "NVIDIA Triton Inference Server contains a vulnerability in the DALI backend, where an attacker could cause uncontrolled resource consumption. A successful exploit of this vulnerability might lead to denial of service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24215"
    },
    {
      "rank": 72,
      "cve_id": "CVE-2026-9101",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00411,
      "epss_percentile": 0.3444,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB, Inc.",
      "product": "Compass",
      "cwe": "CWE-1321",
      "title": "Prototype pollution in csv parsing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9101"
    },
    {
      "rank": 73,
      "cve_id": "CVE-2026-9150",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00409,
      "epss_percentile": 0.34223,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-121",
      "title": "Libsolv: stack-based buffer overflow in libsolv's debian metadata parser when handling sha384/sha512 checksums",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9150"
    },
    {
      "rank": 74,
      "cve_id": "CVE-2026-42834",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00408,
      "epss_percentile": 0.342,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows Admin Center in Azure Portal",
      "cwe": "CWE-59",
      "title": "Windows Admin Center in Azure Portal Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42834"
    },
    {
      "rank": 75,
      "cve_id": "CVE-2026-3592",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00406,
      "epss_percentile": 0.33946,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ISC",
      "product": "BIND 9",
      "cwe": "CWE-408",
      "title": "Amplification vulnerabilities via self-pointed glue records",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3592"
    },
    {
      "rank": 76,
      "cve_id": "CVE-2026-3985",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00405,
      "epss_percentile": 0.33925,
      "kev": false,
      "kev_due_at": null,
      "vendor": "constantcontact",
      "product": "Creative Mail – Easier WordPress & WooCommerce Email Marketing",
      "cwe": "CWE-89",
      "title": "Creative Mail – Easier WordPress & WooCommerce Email Marketing <= 1.6.9 - Unauthenticated SQL Injection via 'checkout_uuid' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3985"
    },
    {
      "rank": 77,
      "cve_id": "CVE-2026-47372",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00397,
      "epss_percentile": 0.33032,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RRWO",
      "product": "Crypt::SaltedHash",
      "cwe": "CWE-338",
      "title": "Crypt::SaltedHash versions through 0.09 for Perl generate insecure random values for salts",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47372"
    },
    {
      "rank": 78,
      "cve_id": "CVE-2026-9112",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00396,
      "epss_percentile": 0.32951,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in GPU in Google Chrome on Windows prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9112"
    },
    {
      "rank": 79,
      "cve_id": "CVE-2026-9118",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00396,
      "epss_percentile": 0.3295,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in XR in Google Chrome on Windows prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9118"
    },
    {
      "rank": 80,
      "cve_id": "CVE-2026-9126",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00396,
      "epss_percentile": 0.3295,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in DOM in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9126"
    },
    {
      "rank": 81,
      "cve_id": "CVE-2026-20240",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00396,
      "epss_percentile": 0.32998,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk Enterprise",
      "cwe": "CWE-20",
      "title": "Denial of Service through coldToFrozen.sh Script in Splunk Enterprise",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20240"
    },
    {
      "rank": 82,
      "cve_id": "CVE-2026-8486",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00395,
      "epss_percentile": 0.32854,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Progress Software",
      "product": "MOVEit Automation",
      "cwe": "CWE-770",
      "title": "Allocation of resources without limits or throttling vulnerability in Progress Software MOVEit Automation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8486"
    },
    {
      "rank": 83,
      "cve_id": "CVE-2026-47373",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00393,
      "epss_percentile": 0.32633,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RRWO",
      "product": "Crypt::SaltedHash",
      "cwe": "CWE-208",
      "title": "Crypt::SaltedHash versions through 0.09 for Perl is susceptible to timing attacks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47373"
    },
    {
      "rank": 84,
      "cve_id": "CVE-2026-39310",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00391,
      "epss_percentile": 0.32445,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TriliumNext",
      "product": "Trilium",
      "cwe": "CWE-284",
      "title": "Trilium Notes: Authentication Bypass in Clipper API for Electron (Desktop) Builds",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39310"
    },
    {
      "rank": 85,
      "cve_id": "CVE-2026-22314",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00387,
      "epss_percentile": 0.31988,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mesalvo",
      "product": "Meona Client Launcher Component",
      "cwe": "CWE-94",
      "title": "Improper Control of Generation of Code ('Code Injection') vulnerability in Mesalvo Meona Client Launcher Component, Mesalvo Meona Server Component enables code execution on other users' systems. This issue affects Meona Client Launcher Component: through 19.06.2020 15:11:49; Meona Server Component: through 2025.04 5+323020.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22314"
    },
    {
      "rank": 86,
      "cve_id": "CVE-2026-6456",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00385,
      "epss_percentile": 0.31824,
      "kev": false,
      "kev_due_at": null,
      "vendor": "beycanpress",
      "product": "Account Switcher",
      "cwe": "CWE-287",
      "title": "Account Switcher <= 1.0.2 - Authenticated (Subscriber+) Authentication Bypass to Privilege Escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6456"
    },
    {
      "rank": 87,
      "cve_id": "CVE-2026-24188",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00385,
      "epss_percentile": 0.3179,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "TensorRT",
      "cwe": "CWE-787",
      "title": "NVIDIA TensorRT contains a vulnerability where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to data tampering.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24188"
    },
    {
      "rank": 88,
      "cve_id": "CVE-2026-24142",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00379,
      "epss_percentile": 0.31217,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "TensorRT-LLM",
      "cwe": "CWE-502",
      "title": "NVIDIA TRT-LLM for any platform contains a deserialization vulnerability and unsafe serialized handle. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24142"
    },
    {
      "rank": 89,
      "cve_id": "CVE-2026-44926",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00375,
      "epss_percentile": 0.3077,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-284",
      "title": "InfoScale CmdServer before 7.4.2 mishandles access control.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44926"
    },
    {
      "rank": 90,
      "cve_id": "CVE-2026-9010",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00366,
      "epss_percentile": 0.29844,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PixelYourSite",
      "product": "Boost",
      "cwe": "CWE-89",
      "title": "Boost <= 2.0.3 - Unauthenticated Blind SQL Injection via Multiple Parameters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9010"
    },
    {
      "rank": 91,
      "cve_id": "CVE-2026-9114",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00365,
      "epss_percentile": 0.2978,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in QUIC in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code inside a sandbox via malicious network traffic. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9114"
    },
    {
      "rank": 92,
      "cve_id": "CVE-2026-9137",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00365,
      "epss_percentile": 0.2972,
      "kev": false,
      "kev_due_at": null,
      "vendor": "misp",
      "product": "misp",
      "cwe": "CWE-400",
      "title": "CSP Report Endpoint Log Flooding in MISP via Incorrect Size Limit",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9137"
    },
    {
      "rank": 93,
      "cve_id": "CVE-2026-8488",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00364,
      "epss_percentile": 0.29608,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Progress Software",
      "product": "MOVEit Automation",
      "cwe": "CWE-770",
      "title": "Allocation of resources without limits or throttling vulnerability in Progress Software MOVEit Automation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8488"
    },
    {
      "rank": 94,
      "cve_id": "CVE-2026-2812",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0036,
      "epss_percentile": 0.29217,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Esri",
      "product": "ArcGIS Server",
      "cwe": "CWE-287",
      "title": "Improper Authentication issue in ArcGIS Server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-2812"
    },
    {
      "rank": 95,
      "cve_id": "CVE-2026-8685",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00359,
      "epss_percentile": 0.29098,
      "kev": false,
      "kev_due_at": null,
      "vendor": "infility",
      "product": "Infility Global",
      "cwe": "CWE-89",
      "title": "Infility Global <= 2.15.16 - Authenticated (Subscriber+) SQL Injection via 'orderby' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8685"
    },
    {
      "rank": 96,
      "cve_id": "CVE-2026-47099",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00358,
      "epss_percentile": 0.29006,
      "kev": false,
      "kev_due_at": null,
      "vendor": "storybookjs",
      "product": "telejson",
      "cwe": "CWE-79",
      "title": "TeleJSON < 6.0.0 DOM-based XSS via parse() Function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47099"
    },
    {
      "rank": 97,
      "cve_id": "CVE-2026-7467",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00357,
      "epss_percentile": 0.2889,
      "kev": false,
      "kev_due_at": null,
      "vendor": "edmonparker",
      "product": "Read More & Accordion",
      "cwe": "CWE-269",
      "title": "Read More & Accordion <= 3.5.7 - Privilege Escalation via importData",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7467"
    },
    {
      "rank": 98,
      "cve_id": "CVE-2025-32750",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0035,
      "epss_percentile": 0.28154,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "PowerFlex Manager (Appliance)",
      "cwe": "CWE-548",
      "title": "Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Exposure of Information Through Directory Listing vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-32750"
    },
    {
      "rank": 99,
      "cve_id": "CVE-2026-22315",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00349,
      "epss_percentile": 0.28102,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mesalvo",
      "product": "Meona Client Launcher Component",
      "cwe": "CWE-266",
      "title": "Incorrect Privilege Assignment vulnerability in Mesalvo Meona Client Launcher Component, Mesalvo Meona Server Component enables the export of user data, including cleartext passwords, via the SQL editor. This issue affects Meona Client Launcher Component: through 19.06.2020 15:11:49; Meona Server Component: through 2025.04 5+323020.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22315"
    },
    {
      "rank": 100,
      "cve_id": "CVE-2026-8485",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00348,
      "epss_percentile": 0.27939,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Progress Software",
      "product": "MOVEit Automation",
      "cwe": "CWE-789",
      "title": "Uncontrolled Memory Allocation vulnerability in Progress Software MOVEit Automation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8485"
    },
    {
      "rank": 101,
      "cve_id": "CVE-2026-9133",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00344,
      "epss_percentile": 0.27581,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AWS",
      "product": "RabbitMQ AWS",
      "cwe": "CWE-489",
      "title": "Arbitrary file read in rabbitmq-aws plugin",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9133"
    },
    {
      "rank": 102,
      "cve_id": "CVE-2026-42923",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00339,
      "epss_percentile": 0.26933,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NLnet Labs",
      "product": "Unbound",
      "cwe": "CWE-407",
      "title": "Degradation of service with unbounded NSEC3 hash calculations",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42923"
    },
    {
      "rank": 103,
      "cve_id": "CVE-2026-9065",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00338,
      "epss_percentile": 0.26853,
      "kev": false,
      "kev_due_at": null,
      "vendor": "brainstormforce",
      "product": "Surecart",
      "cwe": "CWE-89",
      "title": "Surecart - SQL Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9065"
    },
    {
      "rank": 104,
      "cve_id": "CVE-2026-32792",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00337,
      "epss_percentile": 0.26729,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NLnet Labs",
      "product": "Unbound",
      "cwe": "CWE-125",
      "title": "Packet of death with DNSCrypt",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32792"
    },
    {
      "rank": 105,
      "cve_id": "CVE-2026-9110",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00337,
      "epss_percentile": 0.26796,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Inappropriate implementation in UI in Google Chrome on Windows prior to 148.0.7778.179 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9110"
    },
    {
      "rank": 106,
      "cve_id": "CVE-2026-45232",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00337,
      "epss_percentile": 0.26801,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RsyncProject",
      "product": "rsync",
      "cwe": "CWE-193",
      "title": "Rsync < 3.4.3 Off-by-One Stack Write via HTTP Proxy",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45232"
    },
    {
      "rank": 107,
      "cve_id": "CVE-2026-5200",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00336,
      "epss_percentile": 0.26586,
      "kev": false,
      "kev_due_at": null,
      "vendor": "acyba",
      "product": "AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress",
      "cwe": "CWE-862",
      "title": "AcyMailing <= 10.8.2 - Missing Authorization to Authenticated (Subscriber+) Privilege Escalation via 'acymailing_router'",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5200"
    },
    {
      "rank": 108,
      "cve_id": "CVE-2026-6728",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00332,
      "epss_percentile": 0.26167,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Revolution Slider",
      "product": "Slider Revolution",
      "cwe": "CWE-200",
      "title": "Slider Revolution <= 7.0.9 - Unauthenticated Sensitive Information Exposure via 'sliders/stream'",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6728"
    },
    {
      "rank": 109,
      "cve_id": "CVE-2026-9121",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0033,
      "epss_percentile": 0.26038,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-125",
      "title": "Out of bounds read in GPU in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9121"
    },
    {
      "rank": 110,
      "cve_id": "CVE-2026-7460",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.0032,
      "epss_percentile": 0.24858,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mailcow",
      "product": "mailcow-dockerized",
      "cwe": "CWE-79",
      "title": "mailcow-dockerized 2026-03b - Stored XSS in Queue Manager via unescaped",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7460"
    },
    {
      "rank": 111,
      "cve_id": "CVE-2026-20238",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0032,
      "epss_percentile": 0.24909,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk AI Toolkit",
      "cwe": "CWE-863",
      "title": "Improper Access Control through Role Inheritance in Splunk AI Toolkit app",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20238"
    },
    {
      "rank": 112,
      "cve_id": "CVE-2026-6394",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00316,
      "epss_percentile": 0.24379,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpdive",
      "product": "Nexa Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE",
      "cwe": "CWE-918",
      "title": "Nexa Blocks <= 1.1.1 - Unauthenticated Blind Server-Side Request Forgery via 'demo_json_file' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6394"
    },
    {
      "rank": 113,
      "cve_id": "CVE-2026-9087",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00312,
      "epss_percentile": 0.23943,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat build of Keycloak 26.4",
      "cwe": "CWE-639",
      "title": "Keycloak: cross-session email verification proof not bound to upstream identity in first-broker-login",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9087"
    },
    {
      "rank": 114,
      "cve_id": "CVE-2026-9149",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00312,
      "epss_percentile": 0.24034,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-122",
      "title": "Libsolv: heap buffer overflow in libsolv repo_add_solv via negative maxsize from crafted .solv file",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9149"
    },
    {
      "rank": 115,
      "cve_id": "CVE-2026-44923",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00309,
      "epss_percentile": 0.23585,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-89",
      "title": "SQL injection in InfoScale VIOM before v9.1.3 allows remote attackers to escalate privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44923"
    },
    {
      "rank": 116,
      "cve_id": "CVE-2026-5293",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00308,
      "epss_percentile": 0.23554,
      "kev": false,
      "kev_due_at": null,
      "vendor": "olivesystem",
      "product": "診断ジェネレータ作成プラグイン",
      "cwe": "CWE-79",
      "title": "診断ジェネレータ作成プラグイン <= 1.4.16 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'js' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5293"
    },
    {
      "rank": 117,
      "cve_id": "CVE-2026-27405",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00307,
      "epss_percentile": 0.23404,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Magepeople inc.",
      "product": "WpBookingly",
      "cwe": "CWE-862",
      "title": "WordPress WpBookingly plugin <= 1.2.9 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27405"
    },
    {
      "rank": 118,
      "cve_id": "CVE-2026-39405",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00303,
      "epss_percentile": 0.23033,
      "kev": false,
      "kev_due_at": null,
      "vendor": "frappe",
      "product": "lms",
      "cwe": "CWE-22",
      "title": "Frappe has Path Transversal via SCORM",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39405"
    },
    {
      "rank": 119,
      "cve_id": "CVE-2026-40094",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00302,
      "epss_percentile": 0.2284,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nimiq",
      "product": "core-rs-albatross",
      "cwe": "CWE-754",
      "title": "nimiq-blockchain: network-libp2p untrusted peer can crash address book via empty peer contact addresses",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40094"
    },
    {
      "rank": 120,
      "cve_id": "CVE-2026-2813",
      "cvss_base": 4.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.003,
      "epss_percentile": 0.22645,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Esri",
      "product": "ArcGIS Server",
      "cwe": "CWE-601",
      "title": "Unvalidated Redirect in ArcGIS Server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-2813"
    },
    {
      "rank": 121,
      "cve_id": "CVE-2026-30691",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00298,
      "epss_percentile": 0.22503,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-79",
      "title": "Cross-Site Scripting (XSS) vulnerability in @cyntler/react-doc-viewer v1.17.1 allows remote attackers to execute arbitrary JavaScript via a crafted .txt file. The TXTRenderer component fails to sanitize file content and explicitly casts raw data as a ReactNode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-30691"
    },
    {
      "rank": 122,
      "cve_id": "CVE-2026-40102",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00295,
      "epss_percentile": 0.22165,
      "kev": false,
      "kev_due_at": null,
      "vendor": "makeplane",
      "product": "plane",
      "cwe": "CWE-943",
      "title": "Plane: ORM Field Reference Injection via `segment` Parameter in Saved Analytics",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40102"
    },
    {
      "rank": 123,
      "cve_id": "CVE-2026-9100",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00295,
      "epss_percentile": 0.22069,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB, Inc.",
      "product": "C Driver",
      "cwe": "CWE-1285",
      "title": "Heap memory out of bounds read and crash in C Driver legacy GridFS file reader",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9100"
    },
    {
      "rank": 124,
      "cve_id": "CVE-2026-8610",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00294,
      "epss_percentile": 0.2202,
      "kev": false,
      "kev_due_at": null,
      "vendor": "conoha",
      "product": "TypeSquare Webfonts for ConoHa",
      "cwe": "CWE-862",
      "title": "TypeSquare Webfonts for ConoHa <= 2.0.4 - Missing Authorization to Authenticated (Subscriber+) Plugin Settings Modification via 'fontThemeUseType' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8610"
    },
    {
      "rank": 125,
      "cve_id": "CVE-2026-24216",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00289,
      "epss_percentile": 0.21513,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "BioNeMo Framework",
      "cwe": "CWE-502",
      "title": "NVIDIA BioNemo for Linux contains a vulnerability where a user could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, and data tampering.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24216"
    },
    {
      "rank": 126,
      "cve_id": "CVE-2026-42383",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00289,
      "epss_percentile": 0.2146,
      "kev": false,
      "kev_due_at": null,
      "vendor": "YITH",
      "product": "YITH WooCommerce Product Add-Ons",
      "cwe": "CWE-89",
      "title": "WordPress YITH WooCommerce Product Add-Ons plugin <= 4.29.0 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42383"
    },
    {
      "rank": 127,
      "cve_id": "CVE-2026-39311",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00288,
      "epss_percentile": 0.21318,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TriliumNext",
      "product": "Trilium",
      "cwe": "CWE-79",
      "title": "Trilium Notes: Stored XSS Leads to Unauthorized Remote Code Execution (RCE) via Unsanitized SVG Attachments",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39311"
    },
    {
      "rank": 128,
      "cve_id": "CVE-2026-9059",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00287,
      "epss_percentile": 0.21263,
      "kev": false,
      "kev_due_at": null,
      "vendor": "awesomemotive",
      "product": "NextGEN Gallery",
      "cwe": "CWE-89",
      "title": "NextGEN Gallery - SQL Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9059"
    },
    {
      "rank": 129,
      "cve_id": "CVE-2026-5075",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00285,
      "epss_percentile": 0.21084,
      "kev": false,
      "kev_due_at": null,
      "vendor": "smub",
      "product": "All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic",
      "cwe": "CWE-200",
      "title": "All in One SEO <= 4.9.7 - Authenticated (Contributor+) Sensitive Information Exposure via 'internalOptions' Localized Script Data",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5075"
    },
    {
      "rank": 130,
      "cve_id": "CVE-2026-45444",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00282,
      "epss_percentile": 0.20735,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WP Swings",
      "product": "Gift Cards For WooCommerce Pro",
      "cwe": "CWE-434",
      "title": "WordPress Gift Cards For WooCommerce Pro plugin <= 4.2.6 - Arbitrary File Upload vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45444"
    },
    {
      "rank": 131,
      "cve_id": "CVE-2026-43617",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00282,
      "epss_percentile": 0.20725,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RsyncProject",
      "product": "rsync",
      "cwe": "CWE-289",
      "title": "Rsync < 3.4.3 Authorization Bypass via Hostname Resolution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43617"
    },
    {
      "rank": 132,
      "cve_id": "CVE-2026-8487",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0028,
      "epss_percentile": 0.20531,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Progress Software",
      "product": "MOVEit Automation",
      "cwe": "CWE-276",
      "title": "Incorrect default permissions vulnerability in Progress Software MOVEit Automation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8487"
    },
    {
      "rank": 133,
      "cve_id": "CVE-2026-7462",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00275,
      "epss_percentile": 0.20014,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vatanyazilim",
      "product": "VatanSMS WP SMS",
      "cwe": "CWE-79",
      "title": "VatanSMS WP SMS <= 1.01 - Reflected Cross-Site Scripting via 'page' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7462"
    },
    {
      "rank": 134,
      "cve_id": "CVE-2026-7385",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00271,
      "epss_percentile": 0.19415,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Decent Comments",
      "cwe": null,
      "title": "Decent Comments < 3.0.2 - Unauthenticated Email Address Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7385"
    },
    {
      "rank": 135,
      "cve_id": "CVE-2026-4293",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00271,
      "epss_percentile": 0.19448,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kieback & Peter",
      "product": "DDC4002",
      "cwe": "CWE-79",
      "title": "Kieback & Peter DDC Building Controllers Cross-site Scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4293"
    },
    {
      "rank": 136,
      "cve_id": "CVE-2026-9122",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00269,
      "epss_percentile": 0.19153,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-125",
      "title": "Out of bounds read in GPU in Google Chrome on Mac prior to 148.0.7778.179 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9122"
    },
    {
      "rank": 137,
      "cve_id": "CVE-2026-8624",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00266,
      "epss_percentile": 0.18903,
      "kev": false,
      "kev_due_at": null,
      "vendor": "etspring",
      "product": "LJ comments import: reloaded",
      "cwe": "CWE-79",
      "title": "LJ comments import: reloaded <= 0.97.1 - Reflected Cross-Site Scripting via PHP_SELF Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8624"
    },
    {
      "rank": 138,
      "cve_id": "CVE-2026-8626",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00266,
      "epss_percentile": 0.18903,
      "kev": false,
      "kev_due_at": null,
      "vendor": "owencutajar",
      "product": "SponsorMe",
      "cwe": "CWE-79",
      "title": "SponsorMe <= 0.5.2 - Reflected Cross-Site Scripting via PHP_SELF Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8626"
    },
    {
      "rank": 139,
      "cve_id": "CVE-2026-9117",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00265,
      "epss_percentile": 0.18525,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-843",
      "title": "Type Confusion in GFX in Google Chrome on Linux, ChromeOS prior to 148.0.7778.179 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted video file. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9117"
    },
    {
      "rank": 140,
      "cve_id": "CVE-2026-21836",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00264,
      "epss_percentile": 0.18417,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCLSoftware",
      "product": "DominoIQ",
      "cwe": "CWE-862",
      "title": "HCL DominoIQ is affected by broken access control",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21836"
    },
    {
      "rank": 141,
      "cve_id": "CVE-2026-6566",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00264,
      "epss_percentile": 0.18493,
      "kev": false,
      "kev_due_at": null,
      "vendor": "smub",
      "product": "Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery",
      "cwe": "CWE-639",
      "title": "Photo Gallery, Sliders, Proofing and Themes <= 4.2.0 - Insecure Direct Object Reference to Authenticated (Subscriber+) Image Deletion via REST API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6566"
    },
    {
      "rank": 142,
      "cve_id": "CVE-2026-9057",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00261,
      "epss_percentile": 0.17978,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Talend",
      "product": "Talend Administration Center",
      "cwe": null,
      "title": "Security fix for Qlik Talend Administration Center URL access control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9057"
    },
    {
      "rank": 143,
      "cve_id": "CVE-2026-9124",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00261,
      "epss_percentile": 0.17976,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Input in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9124"
    },
    {
      "rank": 144,
      "cve_id": "CVE-2026-7613",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00255,
      "epss_percentile": 0.17326,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pixelyoursite",
      "product": "Cost of Goods by PixelYourSite",
      "cwe": "CWE-79",
      "title": "Cost of Goods by PixelYourSite <= 1.2.12 - Unauthenticated Stored Cross-Site Scripting via Cost of Goods Import",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7613"
    },
    {
      "rank": 145,
      "cve_id": "CVE-2026-44608",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00255,
      "epss_percentile": 0.17343,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NLnet Labs",
      "product": "Unbound",
      "cwe": "CWE-413",
      "title": "Use after free and crash under special conditions in RPZ code",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44608"
    },
    {
      "rank": 146,
      "cve_id": "CVE-2026-5776",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00252,
      "epss_percentile": 0.16899,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Email Encoder",
      "cwe": null,
      "title": "Email Encoder < 2.4.7 - Unauthenticated Stored XSS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5776"
    },
    {
      "rank": 147,
      "cve_id": "CVE-2026-42960",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00249,
      "epss_percentile": 0.16582,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NLnet Labs",
      "product": "Unbound",
      "cwe": "CWE-349",
      "title": "Possible cache poisoning via promiscuous records for the authority section",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42960"
    },
    {
      "rank": 148,
      "cve_id": "CVE-2026-44392",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00249,
      "epss_percentile": 0.16552,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Six Apart Ltd.",
      "product": "Movable Type",
      "cwe": "CWE-862",
      "title": "Missing authorization vulnerability exists in Movable Type. Under certain conditions, when a user without administrator privileges signs in to the product, unintended update processing may be executed.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44392"
    },
    {
      "rank": 149,
      "cve_id": "CVE-2025-15369",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00248,
      "epss_percentile": 0.16429,
      "kev": false,
      "kev_due_at": null,
      "vendor": "xpro",
      "product": "Xpro Addons — 140+ Widgets for Elementor",
      "cwe": "CWE-862",
      "title": "Xpro Addons — 140+ Widgets for Elementor <= 1.5.0 - Missing Authorization to Unauthenticated Xpro Template Creation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-15369"
    },
    {
      "rank": 150,
      "cve_id": "CVE-2026-8038",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00246,
      "epss_percentile": 0.16097,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mcinvale",
      "product": "Faces of Users",
      "cwe": "CWE-79",
      "title": "Faces of Users <= 0.0.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'default' Shortcode Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8038"
    },
    {
      "rank": 151,
      "cve_id": "CVE-2026-6397",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00245,
      "epss_percentile": 0.16058,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cvmh",
      "product": "Sticky",
      "cwe": "CWE-79",
      "title": "Sticky <= 2.5.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'readmoretext' Shortcode Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6397"
    },
    {
      "rank": 152,
      "cve_id": "CVE-2026-6549",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00245,
      "epss_percentile": 0.16057,
      "kev": false,
      "kev_due_at": null,
      "vendor": "goback2",
      "product": "Logo Manager For Enamad",
      "cwe": "CWE-79",
      "title": "Logo Manager For Enamad <= 0.7.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'title' Shortcode Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6549"
    },
    {
      "rank": 153,
      "cve_id": "CVE-2026-26028",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00242,
      "epss_percentile": 0.15675,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cryptpad",
      "product": "cryptpad",
      "cwe": "CWE-79",
      "title": "CryptPad: Sanitizer Bypass in Diffmarked.js Allows Arbitrary HTML Injection and Potential XSS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-26028"
    },
    {
      "rank": 154,
      "cve_id": "CVE-2026-9129",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00239,
      "epss_percentile": 0.15254,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Altium",
      "product": "Altium Enterprise Server",
      "cwe": "CWE-22",
      "title": "Path Traversal in Altium Enterprise Server Viewer StorageController Allows Arbitrary File Read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9129"
    },
    {
      "rank": 155,
      "cve_id": "CVE-2026-6404",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00239,
      "epss_percentile": 0.15244,
      "kev": false,
      "kev_due_at": null,
      "vendor": "simonholliday",
      "product": "Anomify AI – Anomaly Detection and Alerting",
      "cwe": "CWE-79",
      "title": "Anomify AI <= 0.3.6 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'anomify_api_key' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6404"
    },
    {
      "rank": 156,
      "cve_id": "CVE-2026-39960",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0023,
      "epss_percentile": 0.14052,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mantisbt",
      "product": "mantisbt",
      "cwe": "CWE-79",
      "title": "MantisBT is Vulnerable to Stored XSS through Custom Field Textarea Values",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39960"
    },
    {
      "rank": 157,
      "cve_id": "CVE-2026-6399",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0023,
      "epss_percentile": 0.14047,
      "kev": false,
      "kev_due_at": null,
      "vendor": "yog2515",
      "product": "General Options",
      "cwe": "CWE-79",
      "title": "General Options <= 1.1.0 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'ad_contact_number' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6399"
    },
    {
      "rank": 158,
      "cve_id": "CVE-2026-9136",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00229,
      "epss_percentile": 0.14,
      "kev": false,
      "kev_due_at": null,
      "vendor": "misp",
      "product": "misp",
      "cwe": "CWE-639",
      "title": "Unauthorized ShadowAttribute modification in MISP via client-supplied identifier",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9136"
    },
    {
      "rank": 159,
      "cve_id": "CVE-2026-35014",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00229,
      "epss_percentile": 0.13905,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openises",
      "product": "tickets",
      "cwe": "CWE-79",
      "title": "Open ISES Tickets < 3.44.2 Reflected XSS via routes_nm.php ticket_id Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35014"
    },
    {
      "rank": 160,
      "cve_id": "CVE-2026-5783",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00225,
      "epss_percentile": 0.13494,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Beyaz Computer Software Design Industry and Trade Ltd. Co.",
      "product": "CityPLus",
      "cwe": "CWE-79",
      "title": "Reflected XSS in Beyaz Computer's CityPLus",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5783"
    },
    {
      "rank": 161,
      "cve_id": "CVE-2026-9115",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00224,
      "epss_percentile": 0.13355,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-693",
      "title": "Insufficient policy enforcement in Service Worker in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9115"
    },
    {
      "rank": 162,
      "cve_id": "CVE-2026-2955",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00223,
      "epss_percentile": 0.13231,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wupsales",
      "product": "AI Chatbot & Workflow Automation by AIWU",
      "cwe": "CWE-79",
      "title": "AI Chatbot & Workflow Automation by AIWU <= 1.4.14 - Unauthenticated Stored Cross-Site Scripting via 'X-Forwarded-For' Header",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-2955"
    },
    {
      "rank": 163,
      "cve_id": "CVE-2026-8627",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00221,
      "epss_percentile": 0.12963,
      "kev": false,
      "kev_due_at": null,
      "vendor": "lykich",
      "product": "Correct Prices",
      "cwe": "CWE-79",
      "title": "Correct Prices <= 1.0 - Reflected Cross-Site Scripting via PHP_SELF Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8627"
    },
    {
      "rank": 164,
      "cve_id": "CVE-2026-35007",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00221,
      "epss_percentile": 0.129,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openises",
      "product": "tickets",
      "cwe": "CWE-79",
      "title": "Open ISES Tickets < 3.44.2 Reflected XSS via single_unit.php id Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35007"
    },
    {
      "rank": 165,
      "cve_id": "CVE-2026-35008",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00221,
      "epss_percentile": 0.12899,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openises",
      "product": "tickets",
      "cwe": "CWE-79",
      "title": "Open ISES Tickets < 3.44.2 Reflected XSS via single.php ticket_id Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35008"
    },
    {
      "rank": 166,
      "cve_id": "CVE-2026-35009",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00221,
      "epss_percentile": 0.12899,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openises",
      "product": "tickets",
      "cwe": "CWE-79",
      "title": "Open ISES Tickets < 3.44.2 Reflected XSS via add_note.php ticket_id Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35009"
    },
    {
      "rank": 167,
      "cve_id": "CVE-2026-35010",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00221,
      "epss_percentile": 0.12899,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openises",
      "product": "tickets",
      "cwe": "CWE-79",
      "title": "Open ISES Tickets < 3.44.2 Reflected XSS via patient_JF.php ticket_id Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35010"
    },
    {
      "rank": 168,
      "cve_id": "CVE-2026-35011",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00221,
      "epss_percentile": 0.129,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openises",
      "product": "tickets",
      "cwe": "CWE-79",
      "title": "Open ISES Tickets < 3.44.2 Reflected XSS via opena.php frm_call Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35011"
    },
    {
      "rank": 169,
      "cve_id": "CVE-2026-35012",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00221,
      "epss_percentile": 0.12901,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openises",
      "product": "tickets",
      "cwe": "CWE-79",
      "title": "Open ISES Tickets < 3.44.2 Reflected XSS via add_facnote.php ticket_id Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35012"
    },
    {
      "rank": 170,
      "cve_id": "CVE-2026-35013",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00221,
      "epss_percentile": 0.129,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openises",
      "product": "tickets",
      "cwe": "CWE-79",
      "title": "Open ISES Tickets < 3.44.2 Reflected XSS via street_view.php thelat and thelng Parameters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35013"
    },
    {
      "rank": 171,
      "cve_id": "CVE-2026-35015",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00221,
      "epss_percentile": 0.12899,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openises",
      "product": "tickets",
      "cwe": "CWE-79",
      "title": "Open ISES Tickets < 3.44.2 Reflected XSS via do_unit_mail.php the_ticket Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35015"
    },
    {
      "rank": 172,
      "cve_id": "CVE-2026-35016",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00221,
      "epss_percentile": 0.129,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openises",
      "product": "tickets",
      "cwe": "CWE-79",
      "title": "Open ISES Tickets < 3.44.2 Reflected XSS via search.php frm_query Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35016"
    },
    {
      "rank": 173,
      "cve_id": "CVE-2026-44933",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0022,
      "epss_percentile": 0.12769,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SUSE",
      "product": "SUSE Linux Enterprise",
      "cwe": "CWE-35",
      "title": "Path Traversal in Plugin Loading in libzypp",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44933"
    },
    {
      "rank": 174,
      "cve_id": "CVE-2026-9113",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00218,
      "epss_percentile": 0.12503,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-125",
      "title": "Out of bounds read in GPU in Google Chrome on Mac prior to 148.0.7778.179 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9113"
    },
    {
      "rank": 175,
      "cve_id": "CVE-2026-9116",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00218,
      "epss_percentile": 0.12503,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-693",
      "title": "Insufficient policy enforcement in ServiceWorker in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9116"
    },
    {
      "rank": 176,
      "cve_id": "CVE-2026-44924",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00208,
      "epss_percentile": 0.11253,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-79",
      "title": "InfoScale VIOM 9.1.3 allows XSS.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44924"
    },
    {
      "rank": 177,
      "cve_id": "CVE-2026-27424",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00206,
      "epss_percentile": 0.11046,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WP Chill",
      "product": "Image Photo Gallery Final Tiles Grid",
      "cwe": "CWE-862",
      "title": "WordPress Image Photo Gallery Final Tiles Grid plugin <= 3.6.11 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27424"
    },
    {
      "rank": 178,
      "cve_id": "CVE-2026-22554",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.002,
      "epss_percentile": 0.10213,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MediaArea",
      "product": "MediaInfoLib",
      "cwe": "CWE-122",
      "title": "MediaArea MediaInfoLib Channel Splitting heap-based buffer overflow vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22554"
    },
    {
      "rank": 179,
      "cve_id": "CVE-2026-44925",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00198,
      "epss_percentile": 0.10003,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-352",
      "title": "Cross-Site Request Forgery (CSRF) vulnerability in InfoScale v.9.1.3 Operations Manager (VIOM) allows an attacker to force the user with an active session into clicking a malicious HTML link, which triggers unintended modifications on VIOM web application without the user's knowledge.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44925"
    },
    {
      "rank": 180,
      "cve_id": "CVE-2026-45443",
      "cvss_base": 5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00194,
      "epss_percentile": 0.09493,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ADD-ONS.ORG",
      "product": "PDF for Elementor Forms + Drag And Drop Template Builder",
      "cwe": "CWE-862",
      "title": "WordPress PDF for Elementor Forms + Drag And Drop Template Builder plugin <= 5.5.1 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45443"
    },
    {
      "rank": 181,
      "cve_id": "CVE-2026-8419",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00191,
      "epss_percentile": 0.09097,
      "kev": false,
      "kev_due_at": null,
      "vendor": "submone",
      "product": "Amazon Scraper",
      "cwe": "CWE-352",
      "title": "Amazon Scraper <= 1.1 - Cross-Site Request Forgery to Stored Cross-Site Scripting via Settings Update",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8419"
    },
    {
      "rank": 182,
      "cve_id": "CVE-2026-9123",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00187,
      "epss_percentile": 0.08679,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-122",
      "title": "Heap buffer overflow in Chromecast in Google Chrome on Android, Linux, ChromeOS prior to 148.0.7778.179 allowed a local attacker to execute arbitrary code inside a sandbox via malicious network traffic. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9123"
    },
    {
      "rank": 183,
      "cve_id": "CVE-2026-6401",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00187,
      "epss_percentile": 0.08689,
      "kev": false,
      "kev_due_at": null,
      "vendor": "svil4ok",
      "product": "Bottom Bar",
      "cwe": "CWE-352",
      "title": "Bottom Bar <= 0.1.7 - Cross-Site Request Forgery to Settings Update",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6401"
    },
    {
      "rank": 184,
      "cve_id": "CVE-2026-41054",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00185,
      "epss_percentile": 0.08384,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SUSE",
      "product": "Container suse/sle-micro-rancher/5.3:latest",
      "cwe": "CWE-305",
      "title": "Missing exit out of permission check in haveged could lead to root exploit",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41054"
    },
    {
      "rank": 185,
      "cve_id": "CVE-2026-9084",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00182,
      "epss_percentile": 0.08131,
      "kev": false,
      "kev_due_at": null,
      "vendor": "misp",
      "product": "misp",
      "cwe": "CWE-287",
      "title": "MISP OIDC authentication bypass via automatic email-based account linking under insecure IdP configurations",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9084"
    },
    {
      "rank": 186,
      "cve_id": "CVE-2026-8423",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00179,
      "epss_percentile": 0.07775,
      "kev": false,
      "kev_due_at": null,
      "vendor": "javibola",
      "product": "JaviBola Custom Theme Test",
      "cwe": "CWE-352",
      "title": "JaviBola Custom Theme Test <= 2.0.5 - Cross-Site Request Forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8423"
    },
    {
      "rank": 187,
      "cve_id": "CVE-2025-31973",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00178,
      "epss_percentile": 0.07604,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCL",
      "product": "BigFix Service Management (SM)",
      "cwe": "CWE-1395",
      "title": "HCL BigFix Service Management (SM) is susceptible to a Configuration – 'Insecure Use of Base Image Version'",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-31973"
    },
    {
      "rank": 188,
      "cve_id": "CVE-2026-9056",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00178,
      "epss_percentile": 0.07685,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Talend",
      "product": "Talend Administration Center",
      "cwe": null,
      "title": "Security fix for Qlik Talend Administration Center cross-site scripting vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9056"
    },
    {
      "rank": 189,
      "cve_id": "CVE-2026-6391",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00174,
      "epss_percentile": 0.07162,
      "kev": false,
      "kev_due_at": null,
      "vendor": "eazyserver",
      "product": "Sentence To SEO (keywords, description and tags)",
      "cwe": "CWE-352",
      "title": "Sentence To SEO (keywords, description and tags) <= 1.0 - Cross-Site Request Forgery to Stored Cross-Site Scripting via Settings Page Parameters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6391"
    },
    {
      "rank": 190,
      "cve_id": "CVE-2026-8420",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00174,
      "epss_percentile": 0.07162,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rdbeach",
      "product": "BLOGCHAT Chat System",
      "cwe": "CWE-352",
      "title": "BLOGCHAT Chat System <= 1.3.6.3 - Cross-Site Request Forgery to Stored Cross-Site Scripting via Settings Update",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8420"
    },
    {
      "rank": 191,
      "cve_id": "CVE-2026-6405",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00168,
      "epss_percentile": 0.0658,
      "kev": false,
      "kev_due_at": null,
      "vendor": "simonholliday",
      "product": "Anomify AI – Anomaly Detection and Alerting",
      "cwe": "CWE-352",
      "title": "Anomify AI <= 0.3.6 - Cross-Site Request Forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6405"
    },
    {
      "rank": 192,
      "cve_id": "CVE-2025-11954",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00166,
      "epss_percentile": 0.06328,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Sitemio Information Technologies Trade Ltd. Co.",
      "product": "WISECP",
      "cwe": "CWE-352",
      "title": "CSRF in Sitemio's WISECP",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-11954"
    },
    {
      "rank": 193,
      "cve_id": "CVE-2026-24573",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00166,
      "epss_percentile": 0.0639,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Themeisle",
      "product": "Visualizer",
      "cwe": "CWE-79",
      "title": "WordPress Visualizer plugin < 4.0.0 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24573"
    },
    {
      "rank": 194,
      "cve_id": "CVE-2026-6400",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00163,
      "epss_percentile": 0.05999,
      "kev": false,
      "kev_due_at": null,
      "vendor": "helpstring",
      "product": "Child Height Predictor by Ostheimer",
      "cwe": "CWE-352",
      "title": "Child Height Predictor by Ostheimer <= 1.3 - Cross-Site Request Forgery to Settings Update via Plugin Settings Form",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6400"
    },
    {
      "rank": 195,
      "cve_id": "CVE-2026-8418",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00163,
      "epss_percentile": 0.06023,
      "kev": false,
      "kev_due_at": null,
      "vendor": "askywhale",
      "product": "Games Catalog",
      "cwe": "CWE-352",
      "title": "Games Catalog <= 1.2.0 - Cross-Site Request Forgery to Arbitrary Game/Post Deletion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8418"
    },
    {
      "rank": 196,
      "cve_id": "CVE-2026-6452",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00158,
      "epss_percentile": 0.05523,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ktulhu",
      "product": "Bigfishgames Syndicate",
      "cwe": "CWE-352",
      "title": "Bigfishgames Syndicate <= 1.2 - Cross-Site Request Forgery to Settings Reset and Update",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6452"
    },
    {
      "rank": 197,
      "cve_id": "CVE-2026-8424",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00158,
      "epss_percentile": 0.05523,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jay_patel",
      "product": "Remove Yellow BGBOX",
      "cwe": "CWE-352",
      "title": "Remove Yellow BGBOX <= 1.0 - Cross-Site Request Forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8424"
    },
    {
      "rank": 198,
      "cve_id": "CVE-2025-31985",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00157,
      "epss_percentile": 0.05425,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCL",
      "product": "BigFix Service Management (SM)",
      "cwe": "CWE-200",
      "title": "HCL BigFix Service Management (SM) is affected by a security misconfiguration due to a missing or insecure “X-Content-Type-Options” header",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-31985"
    },
    {
      "rank": 199,
      "cve_id": "CVE-2026-6395",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00153,
      "epss_percentile": 0.05001,
      "kev": false,
      "kev_due_at": null,
      "vendor": "winking",
      "product": "Word 2 Cash",
      "cwe": "CWE-352",
      "title": "Word 2 Cash <= 0.9.2 - Cross-Site Request Forgeryto Stored Cross-Site Scripting via Settings Page",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6395"
    },
    {
      "rank": 200,
      "cve_id": "CVE-2026-29518",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00152,
      "epss_percentile": 0.04892,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RsyncProject",
      "product": "rsync",
      "cwe": "CWE-367",
      "title": "Rsync < 3.4.3 TOCTOU Race Condition Allows Symlink-Based Arbitrary File Write",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-29518"
    },
    {
      "rank": 201,
      "cve_id": "CVE-2023-7346",
      "cvss_base": 4.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0014,
      "epss_percentile": 0.03871,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ledger",
      "product": "Ledger Bitcoin app",
      "cwe": "CWE-682",
      "title": "Ledger Bitcoin App 2.1.0 Address Derivation Error via Miniscript",
      "url": "https://www.cve.org/CVERecord?id=CVE-2023-7346"
    },
    {
      "rank": 202,
      "cve_id": "CVE-2026-43619",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00136,
      "epss_percentile": 0.03473,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RsyncProject",
      "product": "rsync",
      "cwe": "CWE-59",
      "title": "Rsync < 3.4.3 Symlink Race Condition via Path-Based Syscalls",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43619"
    },
    {
      "rank": 203,
      "cve_id": "CVE-2026-40622",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00136,
      "epss_percentile": 0.03474,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NLnet Labs",
      "product": "Unbound",
      "cwe": "CWE-346",
      "title": "Another 'ghost domain names' attack variant",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40622"
    },
    {
      "rank": 204,
      "cve_id": "CVE-2026-47782",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00132,
      "epss_percentile": 0.03197,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Siber Systems, Inc.",
      "product": "Android App \"RoboForm Password Manager\"",
      "cwe": "CWE-357",
      "title": "Android App \"RoboForm Password Manager\" provided by Siber Systems, Inc. handles Android intents without sufficient URL validation, user confirmation nor notification. If a URL to some malicious web page is given through an intent, RoboForm may silently download files without user confirmation nor notification.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47782"
    },
    {
      "rank": 205,
      "cve_id": "CVE-2026-0856",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00126,
      "epss_percentile": 0.02701,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mesalvo",
      "product": "Meona Client Launcher Component",
      "cwe": "CWE-284",
      "title": "Improper Access Control vulnerability in Mesalvo Meona Client Launcher Component, Mesalvo Meona Server Component enables a normal user gaining access to the admin panel. This issue affects Meona Client Launcher Component: through 19.06.2020 15:11:49; Meona Server Component: through 2025.04 5+323020.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0856"
    },
    {
      "rank": 206,
      "cve_id": "CVE-2026-0857",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00101,
      "epss_percentile": 0.01029,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mesalvo",
      "product": "Meona Client Launcher Component",
      "cwe": "CWE-316",
      "title": "Cleartext Storage of Sensitive Information in Memory vulnerability in Mesalvo Meona Client Launcher Component, Mesalvo Meona Server Component. This issue affects Meona Client Launcher Component: through 19.06.2020 15:11:49; Meona Server Component: through 2025.04 5+323020.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0857"
    },
    {
      "rank": 207,
      "cve_id": "CVE-2026-25602",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00089,
      "epss_percentile": 0.00508,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mesalvo",
      "product": "Meona Client Launcher Component",
      "cwe": "CWE-345",
      "title": "Insufficient Verification of Data Authenticity vulnerability in Mesalvo Meona Client Launcher Component, Mesalvo Meona Server Component makes it possible to send messages to any email address. This issue affects Meona Client Launcher Component: through 19.06.2020 15:11:49; Meona Server Component: through 2025.04 5+323020.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25602"
    }
  ],
  "transactions": [
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-40102",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-40102 (makeplane plane). Public exploit reference added."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
